Install
$ agentstack add skill-martian56-claude-engineer-ci-cd-pipeline ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
CI/CD Pipeline
Announce at start: "I'm using claude-engineer:ci-cd-pipeline to generate CI and containerization."
Finish line
CI-green + container-ready. No actual deploy. (Deploy targets/credentials are out of scope for v1.)
What to generate
- GitHub Actions - a polyglot workflow that, on PR and main:
- installs both toolchains (uv for Python, pnpm/Bun for JS) with caching;
- lint (
ruff+eslint/prettier --check); - typecheck (
mypy/pyright+tsc --noEmit); - test (
pytest+vitest run --coverage) using service containers (Postgres/Redis) for integration tests; - build (frontend build + backend image build);
- run the four quality gates (
claude-engineer:testing-and-quality) as the merge condition.
- Multi-stage Dockerfiles - FastAPI (uv builder → slim runtime) and the frontend (Next
output: standaloneor static build) +.dockerignore. These prove the app is container-ready.
Non-negotiables
- CI enforces the same four gates the local commit gate enforces - no weaker checks in CI.
- Caching for both toolchains (don't reinstall the world each run).
- Pin action versions and base images.
Full detail (the complete Actions workflow, service-container config, the multi-stage Dockerfiles, prod compose notes): read references/ci-and-containers.md on demand.
Red flags - STOP
- CI that skips a gate the local gate enforces.
- A Dockerfile that copies
.env/secrets ornode_modules/.venv(use.dockerignore). - Unpinned
latestactions or base images.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: martian56
- Source: martian56/claude-engineer
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.